USB eToken
DigiCert can ship a FIPS-compliant SafeNet eToken with your GeoCerts code signing order. You install the certificate on the token with the DigiCert Hardware Certificate Installer (Windows) and use SafeNet Authentication Client on every machine where you plug in the token to sign.
Protect both eToken passwords. The eToken Password (PIN) unlocks the certificate for signing. The Administrator Password defaults to 48 zeros (000000000000000000000000000000000000000000000000). Store both in a password manager. Too many failed Administrator Password attempts permanently lock the token—DigiCert cannot recover it, and you must buy a new eToken. See Passwords, lockouts, and reissue.
Re-initializing wipes the token. Installing a new certificate with “Re-initialize my token” permanently deletes existing certificates and keys on that eToken. Do not re-initialize a token that still holds certificates you need.
In this section
- Install SafeNet Authentication Client — Windows, macOS, and Linux. Required on every signing machine.
- Install the certificate on the eToken — Confirm delivery, copy the initialization code, run the Hardware Certificate Installer.
- Passwords, lockouts, and reissue — eToken Password vs Administrator Password, reset PIN, locked “JC 0” tokens.
You only need Windows once to install the certificate onto the hardware. After that, SafeNet on Mac or Linux is enough to sign with the same token.
Prerequisites
- DigiCert-supplied eToken delivered (or your own supported SafeNet model)
- Administrator access on the Windows PC used for install
- CertCommand order in an issued / token-shipped state
- A password manager for the eToken Password and Administrator Password
Install SafeNet Authentication Client »